Mahmoud Hamed Profile Banner
Mahmoud Hamed Profile
Mahmoud Hamed

@7odamoo

Followers
3,490
Following
513
Media
129
Statuses
1,057
Explore trending content on Musk Viewer
@7odamoo
Mahmoud Hamed
1 year
Sometimes 404 Not Found hides something :) 1. Found 404 subdomain. 2. Do bruteforce with FFUF and find 200 OK endpoint. 3. Do parameter fuzzing with Arjun. 4. That parameter with vulnerable to XSS.
Tweet media one
21
83
434
@7odamoo
Mahmoud Hamed
1 year
1. Found Contact Us form. 2. Injection of special characters was not allowed. 3. The validation was UI Validation. 4. Injected BXSS payload via Burp.
Tweet media one
16
35
256
@7odamoo
Mahmoud Hamed
2 years
A couple of days ago I found a bug on H1 program but I felt that it might be closed as "NA" so I decided not to report it :( Until I watch @_zwink video "You Don't Make Money for Bugs You Don't Log" So I report it and got $750 :) Thank you @_zwink ❤️
Tweet media one
9
16
214
@7odamoo
Mahmoud Hamed
1 year
see you next week when the customer marks them all as duplicates 🤡
Tweet media one
11
2
159
@7odamoo
Mahmoud Hamed
1 year
It wasn't me, It was ChatGPT🤭
Tweet media one
9
8
155
@7odamoo
Mahmoud Hamed
2 years
I was awarded a $400 bounty on @Hacker0x01 Let's sell those coins before they become $4 😂
Tweet media one
16
1
121
@7odamoo
Mahmoud Hamed
1 year
Waited for more than 4 months to get my H1 cap 👾
Tweet media one
6
2
112
@7odamoo
Mahmoud Hamed
1 year
hoping no more dups today:)
Tweet media one
8
3
110
@7odamoo
Mahmoud Hamed
1 year
All are Duplicates ☺️
Tweet media one
@7odamoo
Mahmoud Hamed
1 year
see you next week when the customer marks them all as duplicates 🤡
Tweet media one
11
2
159
20
4
97
@7odamoo
Mahmoud Hamed
2 years
Found phpLDAPadmin Endpoint ? Try to login as an anonymous user, You will see what the admin can see (Schema for My LDAP Server) Credit @0x_rood #bugbountytips #BugBounty
Tweet media one
@0x_rood
🇸🇦 ROOD | GOAT
3 years
1- use ffuf in subdomain 2- /phpldapadmin/ -> 200 ok 3- admin login page 4- try to access admin panel 5- see check box (anonymous login) 6- access with anonymous and read privileges 7- triaged report with high severity 😎 #bugbountytips #BugBounty
Tweet media one
12
93
325
1
30
94
@7odamoo
Mahmoud Hamed
2 years
In February, I submitted 10 vulnerabilities to 5 programs on @Hacker0x01 . This month was crazy as I got a cold twice. I was very sick and I stayed in the bed doing nothing for almost 2 weeks. But luckily I managed to get some bounties #TogetherWeHitHarder
Tweet media one
10
2
87
@7odamoo
Mahmoud Hamed
1 year
I have a possible DOM XSS but it's unexploitable due unsafe:javascript seems it's because of DomSanitizer in Angular. Does anyone know a bypass for this?
Tweet media one
9
10
84
@7odamoo
Mahmoud Hamed
2 years
I found about 52 XSS in one subdomain with different endpoints and different parameters. I got triaged for the first one and the rest become duplicates for my first one :) I felt the company is thinking like, We will make this f**king subdomain down😂
Tweet media one
11
2
83
@7odamoo
Mahmoud Hamed
1 year
Got duplicate >> Wait until the original report got resolved and then bypass it👀
Tweet media one
4
1
75
@7odamoo
Mahmoud Hamed
1 year
XSS photo album 🫣
Tweet media one
4
0
70
@7odamoo
Mahmoud Hamed
2 years
Just crossed 1k reputation @Hacker0x01 <3
Tweet media one
6
0
70
@7odamoo
Mahmoud Hamed
1 year
I am not an easy competitor💀
Tweet media one
@errorsec_
errorsec_
1 year
So here the race begins for #1 in @Hacker0x01 with @7odamo_ 😂😂 #BugBounty #HackerOne
Tweet media one
3
0
30
7
0
66
@7odamoo
Mahmoud Hamed
3 years
Hi uncle @theXSSrat I think you have to handle this
Tweet media one
6
4
66
@7odamoo
Mahmoud Hamed
1 year
2 weeks ago I got a duplicate on a report, and then 3 days ago I found that the original report got resolved. I found a bypass to it and I reported the bypass. Why could such a team mark a report as 'resolved' when it's still being mitigated and tracked internally?🤔
Tweet media one
12
0
60
@7odamoo
Mahmoud Hamed
1 year
8 months time to bounty - I almost forgot that I submitted this report :)
Tweet media one
5
2
60
@7odamoo
Mahmoud Hamed
2 years
I have just joined @pentabug Red Team.
Tweet media one
6
1
57
@7odamoo
Mahmoud Hamed
1 year
Just got ranked as the #3 in my country for Q2 2023. I was so close to being #1 . Let's make #1 our goal for Q3 2023!
Tweet media one
16
1
58
@7odamoo
Mahmoud Hamed
2 years
bought a new xiaomi headphones with xiaomi bounty :)
Tweet media one
Tweet media two
7
0
47
@7odamoo
Mahmoud Hamed
2 years
Sad 🥲
Tweet media one
8
1
47
@7odamoo
Mahmoud Hamed
1 year
Worked with @sazouki_ to uncover a Stored XSS on @Hacker0x01 , Can't wait to tackle more challenges together 🔥
Tweet media one
6
4
41
@7odamoo
Mahmoud Hamed
2 years
I took my friend @c0nqr0r 's advice and tried Bugcrowd for bug hunting... and now I'm questioning our friendship😂 Thanks, @c0nqr0r for recommending Bugcrowd, I'll stick to HackerOne from now on😂
Tweet media one
5
0
41
@7odamoo
Mahmoud Hamed
2 years
Yay, I was awarded a $$$ bounty on @Hacker0x01 ! Bug Type: XSS 💉 #TogetherWeHitHarder
4
2
38
@7odamoo
Mahmoud Hamed
1 year
I got 3 invites to the same private program at the same time 🤔
Tweet media one
6
1
36
@7odamoo
Mahmoud Hamed
2 years
yay, I was awarded 25 euro a bounty 😂😭
Tweet media one
7
0
36
@7odamoo
Mahmoud Hamed
2 years
If I have a Self Stored XSS in profile via "Name" parameter but the URL of the the profile is constant for all users like: Any idea to get an impact out of this self xss? 🤔
15
4
33
@7odamoo
Mahmoud Hamed
2 years
What do you do when your XSSHunter alert in some admin panel but you can't remember where did you inject your XSS Payload ?
6
3
32
@7odamoo
Mahmoud Hamed
2 years
I've submitted several bugs to them in 3rd parties they use and It was not mentioned on their policy page that they don't pay for 3rd parties :) Now I am asking you guys about your opinion ... "Why do you think that many companies don't pay for the 3rd parties they use?"
Tweet media one
5
1
33
@7odamoo
Mahmoud Hamed
2 years
This was one of the most enjoyable times I have done a collaboration, And we will surely continue to collaborate together in the future to find many tricky bugs🐞
@AlQa3Qa3M0x0101
Mohamed reda ameen
2 years
Me and my bro @7odamo_ collaborate at private program at pentabug and that was the first reward from it ... Thanks to @pentabug for give us this opportunity ♥️♥️
Tweet media one
2
4
19
2
0
27
@7odamoo
Mahmoud Hamed
1 year
@HackenProof No, it's never too late, I started at 52
5
1
26
@7odamoo
Mahmoud Hamed
1 year
some teams are awesome :)
Tweet media one
Tweet media two
4
0
23
@7odamoo
Mahmoud Hamed
1 year
Guys, which tool do you use to extract URLs through Dorking in search engines like Bing, Yahoo, Yandex, and DuckDuckGo? I have tried various tools, but none of them seem to work.
4
1
22
@7odamoo
Mahmoud Hamed
1 year
great finding from the DOM master @Mouhannadlrrx 🫡
@disclosedh1
publiclyDisclosed
1 year
Radancy disclosed a bug submitted by @Mouhannadlrrx : #hackerone #bugbounty
Tweet media one
2
5
21
1
0
22
@7odamoo
Mahmoud Hamed
1 year
Hi it's me "7odamo" Two months ago, I began to feel burned out I thought I could solve the problem by changing the platform that I used to work on. But my condition got worse, and after many attempts, I reached a severe stage of depression....
10
0
20
@7odamoo
Mahmoud Hamed
2 years
@GodfatherOrwa @XHackerx007 It's working😀 But I think 99% it will be duplicated
Tweet media one
6
0
18
@7odamoo
Mahmoud Hamed
11 months
Since Bugcrowd notifies me about the resolved reports, I often get duplicates when submitting a bypass. This happens because all researchers receive the same notification and send the bypasses before me. This is why I like H1, I rarely get duplicates on the bypasses.
1
0
18
@7odamoo
Mahmoud Hamed
1 year
@s3cur3_1337 Good question! Usually, I don't like to work on huge scopes as I am not good at recon. so that target has about 30 live subdomains, and only one of them was giving 404, Isn't it interesting to dig more into that subdomain?
0
0
18
@7odamoo
Mahmoud Hamed
3 years
@HackerOn2Wheels @opensea A hacker finds a critical web vulnerability in billion dollar companies and have two options. Exploit two or three users and make millions of dollars, or report to their #bugbounty and get +7 reputation. I wonder what most will choose… 🤡🤡
1
0
16
@7odamoo
Mahmoud Hamed
2 years
Hoping no more duplicate here 🥲
Tweet media one
0
0
16
@7odamoo
Mahmoud Hamed
2 years
My friend @3bodymo_ made a Web Application and asked me and my friends to do pentest on it, And yeah, I got 30 EGP which is about 1.5 Dollars as a bounty for finding Crtical Bug there. Thank you sir for the bounty 😂♥️♥️ Bug type : business logic #BugBounty
Tweet media one
0
1
14
@7odamoo
Mahmoud Hamed
2 years
If the subdomain is not listed in-scope then it's OOS, Even if the subdomain isn't in the OOS section :)
Tweet media one
@7odamoo
Mahmoud Hamed
2 years
If you found a bug on a subdomain that is not listed on both in-scope/out-of-scope subdomains, would you report it or not?
1
0
4
1
0
13
@7odamoo
Mahmoud Hamed
1 year
It was an amazing experience, Thank you so much for your help @jobertabma !
@3bodymo_
Abdullah Mohamed
1 year
I wanted to share my article about how I used AI to report multiple reports to @Hacker0x01 . We're grateful to @jobertabma for his help in resolving the bounty case, and as a result, me and @7odamo_ were finally rewarded for all the reports we submitted.
Tweet media one
7
17
101
2
1
15
@7odamoo
Mahmoud Hamed
1 year
@mahfujwhh Just the normal one: arjun -u -c 1000
1
5
15
@7odamoo
Mahmoud Hamed
3 years
The Private Key isn't Private 😅
Tweet media one
3
0
14
@7odamoo
Mahmoud Hamed
1 year
@scifiboiahoy Do you mean the methodology for getting duplicates?
2
0
13
@7odamoo
Mahmoud Hamed
2 years
More SQLI is here 😀
Tweet media one
3
0
12
@7odamoo
Mahmoud Hamed
2 years
UPDATE Login CSRF + SXSS =
Tweet media one
1
0
11
@7odamoo
Mahmoud Hamed
2 years
@remonsec oh, you are the real remonsec😍 I started It manually then I get 2 bugs there after that I used google dorking to look for similar subdomains in the same county which use the same technology and have the same parameters after that I test on those subdomains, get the rest of bugs
2
0
11
@7odamoo
Mahmoud Hamed
2 years
@RahmatQurishi @Bugcrowd congratulations bro 💖 btw I never thought to test Idors in the response 😂
2
0
10
@7odamoo
Mahmoud Hamed
1 year
@errorrsec I got lots of positive energy from the Twitter infosec community so sharing tips/writeups is like thanking them for that🙏🤍
1
0
11
@7odamoo
Mahmoud Hamed
1 year
What do you do if you find a bug, but when you begin to write a report about it, you find that it fixed
2
0
10
@7odamoo
Mahmoud Hamed
1 year
@0x_rood & LinkFinder
0
2
11
@7odamoo
Mahmoud Hamed
2 years
Report the bug today and get the bounty next year😂
Tweet media one
5
0
10
@7odamoo
Mahmoud Hamed
2 years
@leetibrahim او الي تكون تغريداته علي هذا الشكل yay I got awarded $20000 tip: work hard و يحطلك هاشتاق bugbounty و bugbountytips 😂😂😂
2
0
8
@7odamoo
Mahmoud Hamed
2 years
XSS in the same subdomain with different endpoint and same "parameter name" but each parameter has different filter so the payload for each parameter is different, Should those two XSS be reported on one or two reports
One Report
23
Two Reports
57
Show the Results
16
3
1
8
@7odamoo
Mahmoud Hamed
1 year
@mahfujwhh @Hacker0x01 congratulations, next time keep it and chain it with other bugs to make it at least high severity
2
0
8
@7odamoo
Mahmoud Hamed
1 year
@RahmatQurishi You are an elite hacker, and understanding that being demotivated is a part of this game will make things better, just keep your mental health well and keep yourself around good people❤️
1
0
7
@7odamoo
Mahmoud Hamed
3 years
A guy with '2' reputation and he received 3 bounties or more (as he has an impact) The lesson: Never give up guys 😂
Tweet media one
0
0
6
@7odamoo
Mahmoud Hamed
2 years
@intigriti Hack on VDPs 🤡
0
0
7
@7odamoo
Mahmoud Hamed
10 months
@ArchAngelDDay @Hacker0x01 seems that I am a bad retester lol
Tweet media one
1
0
7
@7odamoo
Mahmoud Hamed
1 year
@bug_vs_me Yes, We can collab on each other XSS bypasses reports😂
1
0
7
@7odamoo
Mahmoud Hamed
1 year
@BountyOverflow You can do XSS with target="_blank" Check this article:
0
2
6
@7odamoo
Mahmoud Hamed
2 years
THE GODFATHER IS BACK 🤩💥💥
@GodfatherOrwa
Godfather Orwa 🇯🇴
2 years
I back with new account same username handle @GodfatherOrwa So all who know me you can follow me again 😂 And from today A lot of #bugbountytips #bugbountytip And lts get back and make it rain P1s✌️
55
41
287
0
0
6
@7odamoo
Mahmoud Hamed
1 year
@AliHassanKhan_ @mahfujwhh @Hacker0x01 Not all programs do so, I submit this bug + XSS + misconfigured CSRF + CORS misconfiguration= 1-Click ATO = High
0
0
5
@7odamoo
Mahmoud Hamed
1 year
@bugbounty_memes - Report submit - Pending program review - Informative - Pending program review - Informative - Pending program review - Informative
Tweet media one
0
0
5
@7odamoo
Mahmoud Hamed
9 months
اخوياا ♥️♥️
1
0
6
@7odamoo
Mahmoud Hamed
3 years
@h4x0r_dz This guy is in my university LoL 😸
1
0
6
@7odamoo
Mahmoud Hamed
1 year
@bug_vs_me Thanks bro! Accepted as critical
1
0
6
@7odamoo
Mahmoud Hamed
2 years
@ibrahimatix0x01 @bug_vs_me @kassem_S94 @Hacker0x01 bro I am finding this out, what goes around this type of bug 😂💔
Tweet media one
0
0
6
@7odamoo
Mahmoud Hamed
1 year
So I decided to quit the field and try to treat myself. Two months have passed since I struggled with depression. I am now in a better condition I miss you all guys it's been a long break but missed to be in contact with the community
1
0
6
@7odamoo
Mahmoud Hamed
1 year
@bogdantcaciuc7 almost the same :)
Tweet media one
2
0
5
@7odamoo
Mahmoud Hamed
1 year
@roohaa_n Imo the first step is to be good on JS and the rest will be easy.
1
1
6
@7odamoo
Mahmoud Hamed
2 years
Too clear h1 program 😂😂
Tweet media one
0
0
5
@7odamoo
Mahmoud Hamed
2 years
@0xr3dhunt want to try hunting there, but I can smell tons of duplicates from here 😂😭
1
0
5
@7odamoo
Mahmoud Hamed
2 years
Now, 2 swags are coming 🤩
Tweet media one
1
0
4
@7odamoo
Mahmoud Hamed
2 years
@BarbaraTeszler Looks Nice :)
Tweet media one
3
0
4
@7odamoo
Mahmoud Hamed
2 years
@Bugcrowd eat then 😴 and I am feeling stuck and depressed today so I am gonna eat then sleep :_(
2
0
5
@7odamoo
Mahmoud Hamed
2 years
@kassem_S94 @Hacker0x01 How do you get those programs guys?😂💔
2
0
5
@7odamoo
Mahmoud Hamed
1 year
2
0
5
@7odamoo
Mahmoud Hamed
1 year
Hey @errorrsec I will be back to H1 program watch your steps then😁 And for you @bug_vs_me we want to collab on some cool CSP/WAF bypasses it go crazy when we do DOM XSS togther😃 @sazouki_ may we find another cool Stored XSS like what we found before but with higher bounty😆
3
0
5
@7odamoo
Mahmoud Hamed
2 years
@007_isnuoT @Sazouki_ @Hacker0x01 wtf, never expect it would be accepted on any program rather than being rewarded too,At first I thought your screenshot is a joke 🤣🤣
2
0
5
@7odamoo
Mahmoud Hamed
2 years
@ibrahimatix0x01 @AkashHamal0x01 try to play with settings - try to change email for Abc @gmail .com and see what happens to both accounts - maybe after changing your email, request password reset link and don't open it until you return you email to Abc @gmail .com again
3
0
5
@7odamoo
Mahmoud Hamed
1 year
We are doing awc-2023 (Hackerone World Cup) with each other lol 😂 @errorrsec
2
0
5
@7odamoo
Mahmoud Hamed
2 years
@ibrahimatix0x01 He came through a lot of reports for a lot of bug hunters. Most probably he was hard-working person 😂
Tweet media one
1
0
5
@7odamoo
Mahmoud Hamed
2 years
when you found a bug on a new program on h1 that has < 10 triage report, then you will get: +17 reputation +10 impact will you get more points when the program gets more than 10 rewarded reports? I mean whom get 17 reputations for critical bug will get another 40 points later?
1
0
5
@7odamoo
Mahmoud Hamed
1 year
@Mohamed87Khayat 1 is the phishing (a in facebook)
0
0
4
@7odamoo
Mahmoud Hamed
2 years
@sheldonx_1 @UTAustin Our king of misconfigs 😍😍
Tweet media one
1
1
4
@7odamoo
Mahmoud Hamed
1 year
@bug_vs_me @Sazouki_ @Hacker0x01 Thanks bro :D I'd be happy to share the details of the bypass/bug in a write-up once the bug is fixed and I get permission to share it. But what I can tell right now is that the filter was designed to block certain words like "alert", "onerror", "document.ANY", etc..
0
0
4
@7odamoo
Mahmoud Hamed
2 years
If you found a bug on a subdomain that is not listed on both in-scope/out-of-scope subdomains, would you report it or not?
Yes I would report it
37
No I wouldn't report it
12
View results
18
1
0
4